Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2025-21311

Опубликовано: 14 янв. 2025
Источник: msrc
CVSS3: 9.8
EPSS Низкий

Описание

Windows NTLM V1 Elevation of Privilege Vulnerability

Меры по смягчению последствий

Mitigation refers to a setting, common configuration, or general best-practice, existing in a default state, that could reduce the severity of exploitation of a vulnerability. The following mitigations might apply in your situation:

Set the LmCompatabilityLvl to its maximum value (5) for all machines. This will prevent the usage of the older NTLMv1 protocol, while still allowing NTLMv2. Please see Network security: LAN Manager authentication level for more information.

FAQ

According to the CVSS metric, the attack vector is network (AV:N) and the attack complexity is low (AC:L). What does that mean for this vulnerability?

The attack vector is Network (AV:N) because this vulnerability is remotely exploitable and can be exploited from the internet. The attack complexity is Low (AC:L) because an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.

Обновления

ПродуктСтатьяОбновление
Windows Server 2022, 23H2 Edition (Server Core installation)
Windows 11 Version 24H2 for ARM64-based Systems
Windows 11 Version 24H2 for x64-based Systems
Windows Server 2025
Windows Server 2025 (Server Core installation)

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 91%
0.06473
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
5 месяцев назад

Windows NTLM V1 Elevation of Privilege Vulnerability

CVSS3: 9.8
github
5 месяцев назад

Windows NTLM V1 Elevation of Privilege Vulnerability

CVSS3: 9.8
fstec
5 месяцев назад

Уязвимость реализации протокола NTLMv1 операционных систем Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 91%
0.06473
Низкий

9.8 Critical

CVSS3